CVE-2023-46747
26.10.2023, 21:15
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.Note: Software versions which have reached End of Technical Support (EoTS) are not evaluatedEnginsight
Vendor | Product | Version |
---|---|---|
f5 | big-ip_access_policy_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_access_policy_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_access_policy_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_access_policy_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_access_policy_manager | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_advanced_firewall_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_advanced_firewall_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_advanced_firewall_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_advanced_firewall_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_advanced_firewall_manager | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_advanced_web_application_firewall | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_advanced_web_application_firewall | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_advanced_web_application_firewall | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_advanced_web_application_firewall | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_advanced_web_application_firewall | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_carrier-grade_nat | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_carrier-grade_nat | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_carrier-grade_nat | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_carrier-grade_nat | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_carrier-grade_nat | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_ddos_hybrid_defender | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_ddos_hybrid_defender | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_ddos_hybrid_defender | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_ddos_hybrid_defender | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_ddos_hybrid_defender | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_ssl_orchestrator | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_ssl_orchestrator | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_ssl_orchestrator | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_ssl_orchestrator | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_ssl_orchestrator | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_domain_name_system | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_domain_name_system | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_domain_name_system | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_domain_name_system | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_domain_name_system | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_local_traffic_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_local_traffic_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_local_traffic_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_local_traffic_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_local_traffic_manager | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_policy_enforcement_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_policy_enforcement_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_policy_enforcement_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_policy_enforcement_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_policy_enforcement_manager | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_automation_toolchain | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_automation_toolchain | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_automation_toolchain | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_automation_toolchain | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_automation_toolchain | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_container_ingress_services | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_container_ingress_services | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_container_ingress_services | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_container_ingress_services | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_container_ingress_services | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_application_security_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_application_security_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_application_security_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_application_security_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_application_security_manager | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_analytics | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_analytics | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_analytics | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_analytics | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_analytics | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_application_acceleration_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_application_acceleration_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_application_acceleration_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_application_acceleration_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_application_acceleration_manager | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_application_visibility_and_reporting | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_application_visibility_and_reporting | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_application_visibility_and_reporting | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_application_visibility_and_reporting | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_application_visibility_and_reporting | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_fraud_protection_services | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_fraud_protection_services | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_fraud_protection_services | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_fraud_protection_services | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_fraud_protection_services | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_global_traffic_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_global_traffic_manager | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_global_traffic_manager | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_global_traffic_manager | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_global_traffic_manager | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_link_controller | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_link_controller | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_link_controller | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_link_controller | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_link_controller | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_webaccelerator | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_webaccelerator | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_webaccelerator | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_webaccelerator | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_webaccelerator | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
f5 | big-ip_websafe | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
f5 | big-ip_websafe | 14.1.0 ≤ 𝑥 ≤ 14.1.5 |
f5 | big-ip_websafe | 15.1.0 ≤ 𝑥 ≤ 15.1.10 |
f5 | big-ip_websafe | 16.1.0 ≤ 𝑥 ≤ 16.1.4 |
f5 | big-ip_websafe | 17.1.0 ≤ 𝑥 ≤ 17.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-288 - Authentication Bypass Using an Alternate Path or ChannelA product requires authentication, but the product has an alternate path or channel that does not require authentication.
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
References